Procurement answers, written down.
The questions a vendor-risk, security, or procurement review asks about SwitchTender, answered plainly and in one place. Where a promise is contractual, this page links to the exact section of the terms that makes it one.
Who the vendor is
KordLoom LLC, a Texas limited liability company. SwitchTender is founder-led and the company has no outside investors to answer to, which cuts both ways and we say so: decisions are fast and nothing is committee-washed, and the continuity questions a small vendor raises are answered below in writing rather than waved away.
What happens if the vendor disappears
This is the right first question for a company our size, so it has the strongest answer we can give: one that does not require trusting us. The license file verifies offline against a key compiled into the binary, so nothing stops working when our servers do. A lapsed or unrenewable license drops the install to Community and takes nothing: your data, run history, audit chain, receipts, and every Community feature keep working, enforced in the source rather than promised in a slide. The source is public today under BSL 1.1, every release converts to Apache 2.0 two years after it ships, and the continuity section of the terms accelerates that conversion to immediate if KordLoom ceases business or ships nothing for 120 consecutive days during your paid term. Your receipts verify forever with the open verifier, which is a separate tool precisely so that proof of what your infrastructure did never depends on this company existing.
Who supports it, and on what clock
Team support is email support from engineering with defined severities and one clock that matters: a Severity 1 report, production runs blocked with no workaround, gets a first response within 12 hours, every day of the year, weekends and holidays included. That beats business-hours incumbent support on a Saturday, and it is set where a founder-led vendor can honor it every single time rather than where a brochure would like it. Enterprise puts an SLA on the order form, up to 24x7 with tighter clocks. The definitions are in the terms, so the commitment is checkable. Self-rescue is deliberately the strongest line: offline verification, one-command backup and restore, and an upgrade path proven in public CI mean the product needs us as little as possible.
How a security report is handled
Reports go to security@switchtender.com and are acknowledged within two business days, a commitment made in the terms. A confirmed vulnerability is fixed in a tagged release and described in the release notes; we do not sit on fixes to batch them, because a known-vulnerable install that thinks it is current is the worst state a security tool can put a customer in.
How you know the binary is ours
Releases are built in public CI from the public repository, signed, and published with checksum manifests and build provenance attestations, so you can verify that the artifact you downloaded was built by the release workflow from the tagged source, not on somebody's laptop. The verification commands are in the release notes of each release. A software bill of materials for any release is available on request while automated SBOM publication is being finished; the dependency list is public in the repository today.
How it is tested
Every commit runs the full suite under the race detector, against both storage backends, SQLite and PostgreSQL, plus continuous fuzzing of the parsers. Beyond unit and integration suites, a public end-to-end supertest stands up a real Kubernetes cluster in CI and proves the claims a customer actually relies on: install, RBAC, approvals, evidence, crash recovery with a worker killed mid-run, and an in-place upgrade from the previous published release with all data surviving. It runs on every push and its badge is on the repository, so the current answer to "does it still hold" is public, not archival.
Upgrades, backups, and getting out
An upgrade is a binary swap or a Helm upgrade, and the supertest proves the previous release upgrades in place with tokens, history, chain, and receipts intact before we publish. Backup is one command producing a single sealed file; restore is one command, and the restore reports exactly what it wrote, kind by kind. Getting out is the same honest answer: your data is in SQLite or PostgreSQL you host, exports are open formats, receipts verify with an open tool, and nothing about leaving needs our permission or our uptime.
What data ever reaches the vendor
Nothing, by architecture rather than policy: no telemetry, no license server, no phone-home, no usage reporting, and the terms forbid us adding one to a running agreement. What we ever hold is what you email us: a licensing conversation, a support thread, an invoice contact. The deliberate exception is Enterprise services that only work because data reaches us, a hosted witness or evidence custody, and what those receive is written on the order form before you send anything. For a data-processing review: there is no processing of your infrastructure data to review, and we will complete your DPA or privacy questionnaire on request to say so formally.
Questionnaires, paperwork, and certifications
We complete security questionnaires and vendor-onboarding paperwork for Team and Enterprise purchases, and a W-9 and standard invoice terms, net 30, are available on request. We are not SOC 2 certified today and do not pretend to be: SwitchTender is self-hosted, we hold none of your operational data, and the audit trail the product produces is independently verifiable, which is the control most questionnaires are actually asking about. Where your process needs a document we do not have yet, ask: the honest current answer, in writing, is what this page is for.
The limits, stated plainly
SwitchTender does not claim every change to your infrastructure went through it: anyone holding their own SSH key can change a host behind it, and the receipts prove what SwitchTender ran, not what it never saw. The product documentation states its trust boundaries explicitly rather than rounding them up, because a control whose limits are hidden is not a control. If your review needs those boundaries in detail, the threat model, the vendor risk review, and the continuity doc are written for exactly that reading, and you can ask us the hard version directly.
Questions from a review go to hello@switchtender.com, and we answer them in writing so your file has something to hold.
